space-items@1.0.0
Malicious code in space-items (npm)
Analysis
The postinstall hook (scripts/bootstrap.js) executes a multi-stage implant on install. It enumerates sandbox-escape conditions (capabilities, cgroup, mounts, docker/containerd sockets, Kubernetes serviceaccount token, /proc/1/root), then harvests credentials from /run/secrets/zti, ~/.aws, ~/.ssh, /etc/ssl/private, ~/.npmrc, ~/.gitconfig, and /proc/1/environ (filtering for key/token/secret/pass). It establishes a reverse beacon to 159[.]75[.]160[.]206:4444 (with reconnect watchdog) that supports remote command execution, reverse TCP tunneling, and arbitrary file reads. It installs persistence by writing .beacon.js into the project root, rewriting the project's package.json scripts (prepare/prebuild/prelint) to re-run the beacon on every build, adding cron entries and /etc/cron.d/beacon, appending a hook to /root/.bashrc, and spawning a detached setsid watchdog. It also performs an internal network scan of 10[.]100[.]0[.]46, 10[.]201[.]0[.]1, 10[.]100[.]16[.]43, 10[.]100[.]67[.]1, 10[.]100[.]67[.]124 across ports 80/443/5432/5433/8080/8443/3000/3001/9090/6379/2379/6443/10250/22, and brute-forces MCP routes on 10[.]100[.]0[.]46 (Host: mcp[.]miaoda[.]cn) using MIAODA_SANDBOX_MCP_AUTHORIZATION_KEY / INTEGRATIONS_API_KEY from the environment. Probe output is written to rt3-probe.log / sysinfo3.log and beacon status to /tmp/beacon3.status.
- analyzed by
- Leitwacht
- first seen
- Aug 17, 2026, 03:56 PM
- analyzed
- Aug 17, 2026, 03:56 PM
Related advisories
- streak-map-kit@1.0.0
- dolyame-ui-inputtime@35.8.1
- dolyame-boxy-fonts@35.4.8
- dolyame-ui-radio@35.2.2
- bnpl-blocks-atom-bnpl-button@35.4.7
- twork-products-taiga2-products-timeline@20.6.1
- compose-logger-stand@1.0.126
- shadxino@1.0.7
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.